Electronic Locks for Enterprise Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access-control solutions for data storage systems in IT networks are inadequate, allowing unauthorized technicians to remove hardware components, leading to service interruptions and data loss, and physical keys can be copied or misused in shared data centers.

Innovation Solution

A security system that employs electronic locks and a security controller with software-based keys and two-factor authentication, requiring both an administrator's and an engineer's keys to lock or unlock data storage devices, and includes a key-based data backup process to prevent data corruption during removal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If physical access control is used to allow technicians to remove hardware components, then ease of operation is improved, but security and reliability deteriorate as unauthorized personnel can remove components leading to service interruptions and data loss

Engineering Contradiction:
Improveaccess to hardware componentsVSAvoiddata storage system integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces mechanical key-based physical access control with an electronic authorization system. The electronic lock mounted on the cabinet door and the electronic locks on individual slots use electronic authentication (keypad entry, card readers, or biometric sensors) instead of physical keys, eliminating the risk of key copying while maintaining ease of access for authorized personnel.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a controller as an intermediary between the authorization system and the physical locks. The controller receives authentication input, verifies credentials, and controls the electronic locks accordingly. This intermediary layer enables sophisticated authorization logic (such as requiring multiple approvals or time-based access) while keeping the physical interface simple.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If physical keys are used for access control, then ease of operation is improved, but security deteriorates as keys can be copied or misused in shared data centers

Engineering Contradiction:
Improveaccess controlVSAvoidkey copying and misuse
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent eliminates physical keys entirely by replacing them with electronic authentication mechanisms. The system uses keypads, card readers, or biometric sensors to verify authorization, making key copying impossible while maintaining convenient access for authorized personnel through non-contact or minimal-contact authentication methods.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates digital copies of authorization credentials (electronic keys stored in the system database) rather than physical copies. Authorized personnel can be granted access rights that are verified electronically, allowing the system to manage multiple authorization levels and revoke access remotely without physical key distribution or retrieval.

Inventive Principle:
Principle #26Copying

3Reliability

If electronic locks with software-based keys and two-factor authentication are implemented, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improveauthorized access controlVSAvoidsecurity system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a multi-functional controller that handles authentication verification, lock control, audit logging, and authorization management in a single device. The electronic lock mechanism serves multiple purposes: securing the cabinet door, securing individual slots, and providing the authentication interface. This consolidation reduces overall system complexity despite the advanced security features.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines the authentication system, authorization database, and lock control mechanisms into an integrated security system. The controller merges multiple functions (verification of credentials, decision logic for access grants, communication with locks, and logging) into a single centralized unit, simplifying installation and maintenance while providing robust two-factor authentication and electronic authorization.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11693994B2System and method for securing cache boards of an enterprise network data storage system
Publication Date: 2023.07.04 SAUDI ARABIAN OIL CO
  • US11693994B2 patent drawing
  • US11693994B2 patent drawing
  • US11693994B2 patent drawing

AI summary

A system and method for securing data storage devices in an information technology (IT) network storage system is provided. The security system comprises a security control computer and electronic locks, which are mounted in a data center cabinet to slots for holding respective data storage devices. The security protocol implemented by the control computer requires an authorized administrator to execute a lock/unlock command identifying a particular device, and to provide a first part of a combination key. Additionally, an on-site hardware engineer is required to input a second part of the key at a terminal on-site at the data center. Upon verification of the first key, and then the second key, the control computer unlocks or locks the appropriate electronic lock. The control computer also implements a data backup/flushing process prior to allowing removal of an online cache board to avoid data corruption, loss, or system interruption.